CVE-2023-22271
5.3
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.6 / Impact: 3.6
Source: NVD
Description
Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decrypt a user's password. The attack complexity is high since a successful exploitation requires to already have in possession this encrypted secret.
Affected (2)
Products: Adobe: Experience Manager, Experience Manager Cloud Service
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.5.16.0 | |
| Before 2023.1.0 |
Related CWEs
CWE-261
Weak Encoding for Password
Obscuring a password with a trivial encoding does not protect the password.
CWE-326
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
References (2)
Source: psirt@adobe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.